On Fri, Jul 17, 2026 at 11:01:07AM +0000, [email protected] wrote:
> > +   /* 1 to 8 registers accessed at a time, within the same 8-reg group */
> > +   while (nregs > 0) {
> > +           unsigned int reg_group = ALIGN_DOWN(regidx, 8);
> > +           unsigned int max_reg = min(regidx + nregs, reg_group + 8);
> 
> [Severity: High]
> Can reg_group + 8 overflow? Since regidx and reg_group are 32-bit unsigned
> integers, if a caller passes a register index near the 32-bit maximum
> (for example, 0xFFFFFFF8) and a small nregs value, reg_group + 8 will wrap
> around to 0.
> 
> If max_reg evaluates to 0, ndata becomes 0 - regidx, which can yield a value
> larger than the original nregs. Will this cause out-of-bounds memory accesses
> on the regs buffer when passed to cla_op_launch(), and an infinite loop due to
> underflowing nregs?

We do need to be careful about regidx overflow since all 32 bits are
valid in CLA (custom accel range is 0x00100000-0xffffffff). I'll make
it u64 in this function

Reply via email to